All Products
Search
Document Center

Anti-DDoS:Anti-DDoS Native 2.0 (Subscription)

Last Updated:Jul 15, 2026

This topic describes the billable items, overdue payments, expiration policy, and refund policy of the subscription billing method for Anti-DDoS Native 2.0.

Selection guide

Select an instance

Anti-DDoS Native 2.0 (Subscription) provides the following instance types, each available in Insurance mode and Unlimited mode:

  • Anti-DDoS Native (SMB): Select this instance if your public IP assets are in the same region, the number of IPs is 30 or fewer, and the business bandwidth does not exceed 1,000 Mbit/s. This edition supports only standard cloud assets and does not allow Advanced EIPs.

  • Enterprise: Select this instance if your public IP assets span multiple regions, the number of IPs exceeds 30, or your assets include both IPv4 and IPv6 addresses. This edition supports both standard and enhanced cloud products, with the latter requiring Advanced EIPs.

Important
  • If you deploy services outside the Chinese mainland, we recommend Anti-DDoS Native (Advanced) EIP or Anti-DDoS Proxy (Outside Chinese Mainland). To use Anti-DDoS Native 2.0 (Subscription) instead, contact your pre-sales account manager.

  • To purchase the Anti-DDoS Native (SMB) edition in Unlimited mode or the Enterprise edition in Insurance mode, contact your pre-sales account manager.

  • Advanced EIP assets are automatically assigned to the Anti-DDoS Native 2.0 (Subscription) instance. If a pay-as-you-go instance exists when you purchase a new Advanced EIP, that EIP is preferentially assigned to the pay-as-you-go instance.

Item

Anti-DDoS Native (SMB)

Enterprise

Insurance Mode

Unlimited Mode

Insurance Mode

Unlimited Mode

Mitigation sessions

2 sessions/month

Note

After all mitigation sessions are consumed, your cloud assets retain only Anti-DDoS Basic mitigation capacity.

Unlimited sessions

2 sessions/month

Note

After all mitigation sessions are consumed, your cloud assets retain only Anti-DDoS Basic mitigation capacity.

Unlimited sessions

Mitigation capabilities

Varies by region. For more information, see Regional mitigation capabilities.

Best-effort protection

Varies by region. For more information, see What is Anti-DDoS Native.

Best-effort protection

Protected asset types

Standard cloud products

Standard and advanced cloud products

Network protocol types of public IP assets to protect

An instance protects only one of IPv4 or IPv6.

An instance can protect both IPv4 and IPv6 assets.

Number of regions for asset protection

1

An instance can protect assets that are assigned public IP addresses in all regions in the Chinese mainland.

Number of IPs supported for protection

Select 1 to 29 when you purchase an instance.

Select 30 to 2,000 when you purchase an instance.

For higher specifications, contact your account manager.

Business bandwidth supported for protection

Select 50 to 1,000 Mbit/s when you purchase an instance.

Select any bandwidth with unlimited scale-up, starting at 100 Mbit/s.

Elastic Business Bandwidth

Supports elastic resource usage and uses a daily 95th-percentile billing model by default. For more information, see Pay-as-you-go > Daily 95th percentile metering method.

When enabled, the total business bandwidth becomes 5 times the baseline business bandwidth.

SLS logs

Not supported.

Supported.

Multi-account management

Not supported.

Supported.

Business bandwidth selection

Estimate your service traffic and select an appropriate clean bandwidth when you purchase an instance.

Note

Anti-DDoS measures traffic based on per-minute peak values, which may differ from the statistics shown in other cloud product metrics. The estimation method described here is intended only as a reference for selecting business bandwidth and should not be used as a billing standard.

The system samples bandwidth at 5-minute intervals for both inbound and outbound traffic. For each sample, the higher of the two values is used as the bandwidth for that point. At the end of the month, the system sorts all sample points in descending order, discards the top 5%, and uses the highest remaining value as the estimated bandwidth (the 95th percentile).

The following figure illustrates how estimated bandwidth is calculated over a 30-day period.

image

Upgrade

The following upgrade scenarios are based on mitigation sessions and supported regions. You can also upgrade the business bandwidth and number of IPs as needed.

  • Anti-DDoS Native (SMB) (Insurance Mode)

    • Choose this edition and mode when you need more than two mitigation sessions per month.

    • To protect public IP assets across multiple regions, upgrade to the Enterprise edition in either Unlimited or Insurance mode.

    • For advanced cloud assets, upgrade to the Enterprise edition in either Unlimited or Insurance mode. Anti-DDoS Native (SMB) currently does not support Advanced EIPs.

  • Anti-DDoS Native (SMB) (Unlimited Mode)

    • To protect public IP assets across multiple regions, upgrade to the Enterprise edition in Unlimited mode.

    • For advanced cloud assets, upgrade to the Enterprise edition in Unlimited mode.

  • Enterprise (Insurance Mode)

    If you need more than 2 mitigation sessions per month, upgrade to the Enterprise edition in Unlimited mode.

Note

Anti-DDoS Native (SMB) in Unlimited mode and Enterprise in Insurance Mode are available only for instance upgrades. To purchase a new instance in either of these editions or modes, contact your account manager.

Billing

Total instance fee = Subscription fee (protection feature fee + business bandwidth fee + IP quantity protection fee) + Pay-as-you-go fee (elastic business bandwidth fee).

Important

The total cost of an instance includes subscription fees and pay-as-you-go fees. Be sure to also review the Pay-as-you-go tab.

Note

The Enterprise supports Advanced EIP assets. Standard cloud assets and Advanced EIP assets have the same pricing (traffic, IP count, and feature fees) on subscription instances.

Subscription

  • Protection fee

    The basic fee for using the instance. The unit price varies based on the instance protection mode.

    Instance protection mode

    Unit price(USD/month)

    Anti-DDoS Native (SMB) (Insurance Mode)

    1,950

    Enterprise (Unlimited Mode)

    6,000

  • Bandwidth fee

    Instance protection mode

    Unit price(USD/month/Mbps)

    • Anti-DDoS Native (SMB) (Insurance Mode)

    • Enterprise (Insurance Mode)

    5

    • Anti-DDoS Native (SMB) (Unlimited Mode)

    • Enterprise (Unlimited Mode)

    10

  • IP quantity protection fee

    Charged based on the number of protected asset IPs using tiered pricing. The unit price varies by instance protection mode. If the IP count in the following table does not meet your requirements, contact your account manager.

    Instance protection mode

    Number of IPs

    Unit price(USD/month/instance)

    Anti-DDoS Native (SMB) (Insurance Mode, Unlimited Mode)

    [0, 100]

    24

    Enterprise (Insurance Mode, Unlimited Mode)

    [0, 30]

    0

    (30, 100]

    24

    (100, 300]

    19.2

    (300, 500]

    14.4

    (500, 700]

    12

    (700, 1,000]

    9.6

    For example, if you purchase an Enterprise (Unlimited Mode) instance with 200 IPs, the IP quantity protection fee is calculated as follows:

    • For the 30 IPs within the [0, 30] range, the monthly fee is 0 USD.

    • For the 70 IPs within the (30, 100] range, the monthly fee is 24 x 70 = 1,680 USD.

    • For the 100 IPs within the (100, 300] range, the monthly fee is 19.2 x 100 = 1,920 USD.

    Therefore, the monthly fee for the protected IPs is 1,680 + 1,920 = 3,600 USD.

Pay-as-you-go

Pay-as-you-go includes only the elastic business bandwidth fee.

Daily 95th percentile billing is the default and only metering method for elastic business bandwidth. The business bandwidth increases elastically by 4 times the baseline, making the total business bandwidth 5 times the baseline. For example, if the baseline is 1 Gbit/s, the total business bandwidth is 5 Gbit/s.

When actual traffic exceeds the baseline business bandwidth, traffic is not rate-limited, but additional charges apply for the excess. When actual traffic stays within the baseline, no additional pay-as-you-go fees are incurred. You can query elastic business bandwidth usage in the Billing Center.

Important
  • Starting from 10:00 on May 28, 2026, Anti-DDoS Native no longer supports the monthly 95th percentile billing mode for elastic business bandwidth. Both new and existing customers will have the daily 95th percentile billing enabled by default. Additionally, manual configuration of elastic business bandwidth in the console (such as disabling or enabling the feature, changing the billing mode, or adjusting bandwidth specifications) is no longer supported. For more information, see [Important] Adjustments to Anti-DDoS burstable billing feature.

  • Disabling daily 95th-percentile billing takes effect the next day and can be done only once per month.

Billing mode

Unit price

Cost calculation formula

Daily 95th percentile

USD 1.79/day/Mbit/s

Billable bandwidth x Unit price

How to calculate the billable bandwidth

  1. Calculate the total peak traffic.

    Within a calendar day, sample the peak business traffic at 5-minute intervals. This generates 288 values per day. Remove values during DDoS attacks, and then remove the top five values. Take the maximum of the remaining values.

  2. Calculate the daily 95th percentile billable bandwidth.

    Daily 95th percentile billable bandwidth = min (total peak traffic, total business bandwidth) - baseline business bandwidth. The total business bandwidth is 5 times the baseline business bandwidth.

Monthly 95th percentile

USD 12.5/month/Mbit/s

Billable bandwidth × Validity factor × Unit price

  • How to calculate the billable bandwidth

    1. Calculate the total peak traffic.

      1. Determine the daily peak bandwidth: Within a calendar day, sample the peak business traffic at 5-minute intervals. This generates 288 values per day. Remove values during DDoS attacks, and take the maximum of the remaining values.

      2. Calculate the total peak traffic: Sort the daily peak bandwidth values from a calendar month in descending order. The total peak traffic is the average of the top five values.

    2. Calculate the monthly 95th percentile billable bandwidth.

      Monthly 95th percentile billable bandwidth = min (total peak traffic, total business bandwidth) - baseline business bandwidth.

      • Total business bandwidth: Identify the baseline business bandwidth values that correspond to the top five daily peak bandwidths. The total business bandwidth is five times the maximum of these base bandwidth values.

      • Baseline business bandwidth: This is the value of the baseline business bandwidth on the last day of the calendar month in which the elastic bandwidth feature is active.

  • Validity factor = Number of effective days in the month/Total days in the month. For example, if you enabled the elastic bandwidth feature on July 15, 2024 and did not disable it that month, the number of effective days is 16 (from July 16, 2024 to July 31, 2024). The total number of days in July is 31. The validity factor is 16/31 = 0.51612903.

Billing generation and settlement times are as follows. Actual times are subject to the system.

Billing mode

Billing generation time

Settlement time

Daily 95th percentile

At approximately 10:00 the next day, the elastic business bandwidth bill for the previous calendar day is sent to the Alibaba Cloud account contact via text message, email, and internal message.

At approximately 16:00 the next day, Alibaba Cloud pushes the elastic business bandwidth usage and deducts the corresponding fees from the account balance.

Monthly 95th percentile

At approximately 10:00 on the first day of the following month, the elastic business bandwidth bill for the previous calendar month is sent to the Alibaba Cloud account contact via text message, email, and internal message.

At approximately 11:00 on the third day of the following month, Alibaba Cloud pushes the elastic business bandwidth usage and deducts the corresponding fees from the account balance.

Mitigation session consumption

  • Calculation method: Traffic is recorded at 5-second intervals (12 data points per minute). When attack traffic exceeds N Gbit/s, the system starts accumulating the attack duration (shown as X+Y in the figure). Every 15 minutes (180 data points) of accumulated attack duration consumes one full protection session. For information on how to check your remaining sessions, see Manage instances.image.png

    In the figure, the red line represents the inbound traffic of the protected public IP asset.

    • For public IP assets in the Chinese mainland: N = 20 Gbit/s.

    • For public IP assets outside the Chinese mainland: N = 10 Gbit/s.

  • Example: An asset located in Chinese Mainland is under attack. The instance has 2 protection sessions.

    • First attack: Duration exceeding 20 Gbit/s is 10 minutes.

    • Second attack: Duration exceeding 20 Gbit/s is 12 minutes.

    • Total cumulative duration: 22 minutes.

    Session consumption process:

    1. First session consumption:
      During the second attack, when the cumulative attack duration reaches 15 minutes (10 minutes from the first attack + 5 minutes from the second), the first protection session is consumed. The remaining 7 minutes of the second attack (22 - 15 = 7) are carried forward to the next counting cycle.

    2. Second session consumption:
      If attacks continue within the same month, the carried-forward 7 minutes will accumulate with any new attack duration. When the cumulative duration in this new cycle reaches 15 minutes, the second protection session is consumed.

Bandwidth limit and overage recovery

Bandwidth limit

Enhanced cloud assets have the following bandwidth limits based on region. Standard cloud assets do not have these limits:

Access scenario

Chinese Mainland

Outside Chinese Mainland

Local access
(Client and cloud product in the same region)

20 Gbit/s

2 Gbit/s

Cross-region access
(Client and cloud product in different regions)

Unlimited

100 Mbit/s

Bandwidth overage recovery

  • Overage alerts and mitigation downgrade: Anti-DDoS Native allows business traffic to temporarily exceed the instance bandwidth. When the cumulative monthly overage duration reaches 1 hour, 9 hours, 18 hours, 27 hours, or 36 hours, the system sends a notification through Message Center the next morning (T+1). When the cumulative overage duration reaches 36 hours, Anti-DDoS Native protection is disabled and only Basic protection remains.

  • Three ways to restore Anti-DDoS Native protection: If protection has been disabled, you can restore it using one of the following methods:

    • Method 1: Wait for automatic recovery at 00:00 on the 1st of the next month. No action is required.

    • Method 2: Enable elastic business bandwidth (Anti-DDoS Native 2.0 Enterprise subscription instances only). Protection is restored immediately after enabling. The bandwidth limit increases to 5 times the baseline bandwidth (adding 4 times as elastic bandwidth).

    • Method 3: Upgrade the baseline bandwidth of your instance. Protection is restored immediately after the upgrade.

  • Overage accumulation rules after recovery: After restoring protection using method 2 or 3, the overage handling rules for the remainder of the month are as follows:

    • If 36 hours were already accumulated before recovery: If overage occurs again after recovery, you receive an alert the next day (T+1) and protection is disabled again.

    • If less than 36 hours were accumulated before recovery: Overage duration continues to accumulate after recovery. If the total cumulative duration reaches 36 hours for the month, you receive an alert the next day (T+1) and protection is disabled.

Expiration information

Time period

Impact after expiration

Instance configuration

Within 7 days (inclusive) after expiration

Service stops immediately after expiration. Service is restored after you renew the instance.

Instance configuration is retained.

On the 8th day after expiration

  • The instance is released and cannot be recovered.

  • Any Advanced EIP instances bound to the Anti-DDoS Native instance are also automatically released and cannot be recovered.

  • All instance configurations are permanently deleted and cannot be recovered.

  • The related configurations and data of any Advanced EIP instances bound to the Anti-DDoS Native instance are also permanently deleted and cannot be recovered.

Refund policy

  • Refunds are not supported after you purchase an instance.

  • Traffic charges are covered by a charge protection mechanism. In rare cases, attack traffic may be counted as clean traffic (for example, HTTP GET Flood attacks may cause abnormal outbound traffic increases). In such cases, you can contact technical support to request a reduction or waiver of the abnormal charges on your traffic bill.

    Note

    Provide supporting materials such as server logs or traffic monitoring data (for example, normal and abnormal QPS logs during an HTTP GET Flood attack) to help Alibaba Cloud identify and resolve abnormal charges more quickly.

Payment Overdue

Your account is considered overdue when the available balance (including cash, vouchers, and coupons) cannot cover outstanding bills.

  • Service stops immediately upon overdue. After 15 days of suspension, the instance is released and all configurations are permanently deleted and cannot be recovered.

Important

To avoid service interruption from overdue payments, enable auto-renewal. For more information, see Renewal.

Query

Bill query: You can query bills in the Expenses and Costs console.

Important

Bills generated on day T are typically pushed on day T+1. For large bills, Alibaba Cloud may perform a secondary review and delay the push by 1 to 3 days, combining multiple days of bills.

Usage query: Log on to Traffic Security console and view your usage on the Anti-DDoS Native > Billing Management page.

FAQ

Why does the traffic data in Cloud Monitor and other cloud product metrics differ from the Anti-DDoS traffic data?

Traffic metrics displayed in the Anti-DDoS console are typically higher than those shown in Cloud Monitor or other specific cloud product pages.

Example scenario:
When an ECS instance undergoes a DDoS attack that triggers traffic scrubbing, the Anti-DDoS Basic notification may report a trigger threshold of 2.5 Gbit/s. However, a query in Cloud Monitor for the same period might show an inbound bandwidth of only 1.2 Git/s on the EIP associated with the ECS instance.

This discrepancy arises from three main factors:

  • Measurement stage (pre-scrubbing vs. post-scrubbing)

    • Anti-DDoS data: Captured before traffic scrubbing. It includes all incoming traffic, comprising both legitimate business traffic and malicious attack traffic.

    • Cloud Monitor data: Captured after traffic scrubbing. It reflects only the legitimate traffic that has been filtered and forwarded to the instance, as attack traffic is discarded during the scrubbing process.

  • Monitoring granularity (second-level vs. minute-level)

    • Anti-DDoS: Utilizes second-level granularity to detect attacks, allowing it to capture instantaneous traffic spikes accurately.

    • Cloud Monitor: Typically aggregates EIP traffic data at minute-level intervals. Consequently, instantaneous peaks may be smoothed out in the average, resulting in lower reported values compared to real-time spikes.

  • Monitoring location (network boundary vs. forwarding device)

    • Anti-DDoS: Monitors traffic at the boundary between the Internet and the Alibaba Cloud network, recording all raw inbound traffic.

    • Cloud Monitor: Collects data from forwarding devices closer to the instance, recording only the traffic successfully delivered to the resource.

Note

All public cloud IaaS products, such as ECS, SLB, EIP, and NAT Gateway, may encounter the preceding issue.